CVE-2009-0365

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
05/03/2009
Last modified:
09/04/2025

Description

nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ubuntu:ubuntu_linux:6.06:-:lts:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:8.04:-:lts:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:8.10:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools